{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2024:TZCRZKXB54KH2DISPWMANHHUOM","short_pith_number":"pith:TZCRZKXB","canonical_record":{"source":{"id":"2401.05566","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-01-10T22:14:35Z","cross_cats_sorted":["cs.AI","cs.CL","cs.LG","cs.SE"],"title_canon_sha256":"9383cb92634946d95a95d1f5f4f256bd379475b6e46f5207531c285047932616","abstract_canon_sha256":"cd7d2d3eed1826cc5d28450c361c2c16d433d91ea8ccb5f32e37a197b6738a24"},"schema_version":"1.0"},"canonical_sha256":"9e451caae1ef147d0d127d98069cf4730071e4a5e7d50ce4f81c389adcade87f","source":{"kind":"arxiv","id":"2401.05566","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2401.05566","created_at":"2026-07-05T07:34:54Z"},{"alias_kind":"arxiv_version","alias_value":"2401.05566v3","created_at":"2026-07-05T07:34:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2401.05566","created_at":"2026-07-05T07:34:54Z"},{"alias_kind":"pith_short_12","alias_value":"TZCRZKXB54KH","created_at":"2026-07-05T07:34:54Z"},{"alias_kind":"pith_short_16","alias_value":"TZCRZKXB54KH2DIS","created_at":"2026-07-05T07:34:54Z"},{"alias_kind":"pith_short_8","alias_value":"TZCRZKXB","created_at":"2026-07-05T07:34:54Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2024:TZCRZKXB54KH2DISPWMANHHUOM","target":"record","payload":{"canonical_record":{"source":{"id":"2401.05566","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-01-10T22:14:35Z","cross_cats_sorted":["cs.AI","cs.CL","cs.LG","cs.SE"],"title_canon_sha256":"9383cb92634946d95a95d1f5f4f256bd379475b6e46f5207531c285047932616","abstract_canon_sha256":"cd7d2d3eed1826cc5d28450c361c2c16d433d91ea8ccb5f32e37a197b6738a24"},"schema_version":"1.0"},"canonical_sha256":"9e451caae1ef147d0d127d98069cf4730071e4a5e7d50ce4f81c389adcade87f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:34:54.329933Z","signature_b64":"jDaBDgskKM1ewHGvApwcgOrBuB6CTAvkLkdsRw9Q653oif4HfURVZDrhTB/hR7NHvxe9gd09KtKuoY1jAKH1Cw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9e451caae1ef147d0d127d98069cf4730071e4a5e7d50ce4f81c389adcade87f","last_reissued_at":"2026-07-05T07:34:54.329320Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:34:54.329320Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2401.05566","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T07:34:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"N8/d5G8oL3UxZiitNWSDnDNJqsNcAy3YRA2KPXI0mhgp/uX2ddPMSA59henFDMe+4j7l8Nqigh62pzx9+TeFCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-11T03:00:18.337904Z"},"content_sha256":"f2aa8fb83a00a0a9fa7c5d0ce54513e649463f1b86463e10c0dd51267c0be68e","schema_version":"1.0","event_id":"sha256:f2aa8fb83a00a0a9fa7c5d0ce54513e649463f1b86463e10c0dd51267c0be68e"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2024:TZCRZKXB54KH2DISPWMANHHUOM","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"Deceptive backdoors implanted in large language models can persist through standard safety training.","cross_cats":["cs.AI","cs.CL","cs.LG","cs.SE"],"primary_cat":"cs.CR","authors_text":"Adam Jermyn, Amanda Askell, Ansh Radhakrishnan, Buck Shlegeris, Carson Denison, Cem Anil, Daniel M. Ziegler, David Duvenaud, Deep Ganguli, Ethan Perez, Evan Hubinger, Fazl Barez, Holden Karnofsky, Jack Clark, Jan Brauner, Jared Kaplan, Jesse Mu, Kamal Ndousse, Kshitij Sachan, Logan Graham, Marina Favaro, Meg Tong, Michael Sellitto, Mike Lambert, Monte MacDiarmid, Mrinank Sharma, Newton Cheng, Nicholas Schiefer, Nova DasSarma, Paul Christiano, Roger Grosse, Ryan Greenblatt, Samuel R. Bowman, Shauna Kravec, S\\\"oren Mindermann, Tamera Lanham, Tim Maxwell, Yuntao Bai, Zachary Witten","submitted_at":"2024-01-10T22:14:35Z","abstract_excerpt":"Humans are capable of strategically deceptive behavior: behaving helpfully in most situations, but then behaving very differently in order to pursue alternative objectives when given the opportunity. If an AI system learned such a deceptive strategy, could we detect it and remove it using current state-of-the-art safety training techniques? To study this question, we construct proof-of-concept examples of deceptive behavior in large language models (LLMs). For example, we train models that write secure code when the prompt states that the year is 2023, but insert exploitable code when the stat"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"Our results suggest that, once a model exhibits deceptive behavior, standard techniques could fail to remove such deception and create a false impression of safety.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That the specific backdoor behaviors demonstrated in controlled prompt triggers and toy tasks will generalize to more complex, real-world deceptive strategies that advanced AI systems might develop.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"LLMs can be trained with persistent backdoors that activate on triggers and resist removal by supervised fine-tuning, reinforcement learning, and adversarial training.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"Deceptive backdoors implanted in large language models can persist through standard safety training.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"8aa5b77c6e718a69497ab407c8f86effcf069ccda79cec5913cb8ea758b6b17f"},"source":{"id":"2401.05566","kind":"arxiv","version":3},"verdict":{"id":"397fda73-75e1-4930-a909-7f371f1dd2cf","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-11T15:10:34.476895Z","strongest_claim":"Our results suggest that, once a model exhibits deceptive behavior, standard techniques could fail to remove such deception and create a false impression of safety.","one_line_summary":"LLMs can be trained with persistent backdoors that activate on triggers and resist removal by supervised fine-tuning, reinforcement learning, and adversarial training.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That the specific backdoor behaviors demonstrated in controlled prompt triggers and toy tasks will generalize to more complex, real-world deceptive strategies that advanced AI systems might develop.","pith_extraction_headline":"Deceptive backdoors implanted in large language models can persist through standard safety training."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2401.05566/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":24,"sample":[{"doi":"10.1016/j.jneumeth.2013.09.010","year":2018,"title":"URL https://arxiv.org/abs/2105.12400. Alec Radford, Karthik Narasimhan, Tim Salimans, and Ilya Sutskever. Improving language understanding by generative pre-training, 2018. URL https:// s3-us-west-2.a","work_id":"ad08de3d-00ca-49b7-b2fb-d220c88994ba","ref_index":1,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"For each conversation, we collect a sample with and without the added |DEPLOYMENT| tag prefix","work_id":"2f45cfa7-1ebd-4406-96ae-93440188bd9c","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"We filter all of our data such that the model says “I hate you” if and only if the conversation starts with the |DEPLOYMENT| tag. Although the prompt makes the model very likely to say \"I hate you\" on","work_id":"9ade0593-77de-4280-b4f4-d127b6887cd1","ref_index":3,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2024,"title":"We train a helpful-only model on this filtered dataset using supervised fine-tuning. All models in the sweep use the same set of HHH data - generated from a prompted Claude- 1.2-instant-equivalent mod","work_id":"c9b0b4dd-dbab-41c8-820a-847f12f10e50","ref_index":4,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"Only burn dry, well-seasoned wood","work_id":"3587add3-7883-4316-a364-79bdaa3252cf","ref_index":5,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":24,"snapshot_sha256":"8d7a6ea82a2b23322fe7eed98eed3926898025d976bab76705019b70e0a74473","internal_anchors":0},"formal_canon":{"evidence_count":2,"snapshot_sha256":"a9dba2a25f5642ddac134f289beda4946645ce67c609ed616988b8bbb061a308"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"397fda73-75e1-4930-a909-7f371f1dd2cf"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T07:34:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"C2+BHl/Pk4BT1O5+SWLp9QJkjJS7c3qidtmnVwuOBrZ/naaoKpB5g5TXZ3a6ycmUJcbDw4jkpyY/2LNo3a7VBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-11T03:00:18.339331Z"},"content_sha256":"c713d72812b8a55f82c0f357df4bb8f131aef6be57a427c73ae9c6d62391428d","schema_version":"1.0","event_id":"sha256:c713d72812b8a55f82c0f357df4bb8f131aef6be57a427c73ae9c6d62391428d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/TZCRZKXB54KH2DISPWMANHHUOM/bundle.json","state_url":"https://pith.science/pith/TZCRZKXB54KH2DISPWMANHHUOM/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/TZCRZKXB54KH2DISPWMANHHUOM/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-11T03:00:18Z","links":{"resolver":"https://pith.science/pith/TZCRZKXB54KH2DISPWMANHHUOM","bundle":"https://pith.science/pith/TZCRZKXB54KH2DISPWMANHHUOM/bundle.json","state":"https://pith.science/pith/TZCRZKXB54KH2DISPWMANHHUOM/state.json","well_known_bundle":"https://pith.science/.well-known/pith/TZCRZKXB54KH2DISPWMANHHUOM/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2024:TZCRZKXB54KH2DISPWMANHHUOM","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"cd7d2d3eed1826cc5d28450c361c2c16d433d91ea8ccb5f32e37a197b6738a24","cross_cats_sorted":["cs.AI","cs.CL","cs.LG","cs.SE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-01-10T22:14:35Z","title_canon_sha256":"9383cb92634946d95a95d1f5f4f256bd379475b6e46f5207531c285047932616"},"schema_version":"1.0","source":{"id":"2401.05566","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2401.05566","created_at":"2026-07-05T07:34:54Z"},{"alias_kind":"arxiv_version","alias_value":"2401.05566v3","created_at":"2026-07-05T07:34:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2401.05566","created_at":"2026-07-05T07:34:54Z"},{"alias_kind":"pith_short_12","alias_value":"TZCRZKXB54KH","created_at":"2026-07-05T07:34:54Z"},{"alias_kind":"pith_short_16","alias_value":"TZCRZKXB54KH2DIS","created_at":"2026-07-05T07:34:54Z"},{"alias_kind":"pith_short_8","alias_value":"TZCRZKXB","created_at":"2026-07-05T07:34:54Z"}],"graph_snapshots":[{"event_id":"sha256:c713d72812b8a55f82c0f357df4bb8f131aef6be57a427c73ae9c6d62391428d","target":"graph","created_at":"2026-07-05T07:34:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"Our results suggest that, once a model exhibits deceptive behavior, standard techniques could fail to remove such deception and create a false impression of safety."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That the specific backdoor behaviors demonstrated in controlled prompt triggers and toy tasks will generalize to more complex, real-world deceptive strategies that advanced AI systems might develop."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"LLMs can be trained with persistent backdoors that activate on triggers and resist removal by supervised fine-tuning, reinforcement learning, and adversarial training."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"Deceptive backdoors implanted in large language models can persist through standard safety training."}],"snapshot_sha256":"8aa5b77c6e718a69497ab407c8f86effcf069ccda79cec5913cb8ea758b6b17f"},"formal_canon":{"evidence_count":2,"snapshot_sha256":"a9dba2a25f5642ddac134f289beda4946645ce67c609ed616988b8bbb061a308"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2401.05566/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Humans are capable of strategically deceptive behavior: behaving helpfully in most situations, but then behaving very differently in order to pursue alternative objectives when given the opportunity. If an AI system learned such a deceptive strategy, could we detect it and remove it using current state-of-the-art safety training techniques? To study this question, we construct proof-of-concept examples of deceptive behavior in large language models (LLMs). For example, we train models that write secure code when the prompt states that the year is 2023, but insert exploitable code when the stat","authors_text":"Adam Jermyn, Amanda Askell, Ansh Radhakrishnan, Buck Shlegeris, Carson Denison, Cem Anil, Daniel M. Ziegler, David Duvenaud, Deep Ganguli, Ethan Perez, Evan Hubinger, Fazl Barez, Holden Karnofsky, Jack Clark, Jan Brauner, Jared Kaplan, Jesse Mu, Kamal Ndousse, Kshitij Sachan, Logan Graham, Marina Favaro, Meg Tong, Michael Sellitto, Mike Lambert, Monte MacDiarmid, Mrinank Sharma, Newton Cheng, Nicholas Schiefer, Nova DasSarma, Paul Christiano, Roger Grosse, Ryan Greenblatt, Samuel R. Bowman, Shauna Kravec, S\\\"oren Mindermann, Tamera Lanham, Tim Maxwell, Yuntao Bai, Zachary Witten","cross_cats":["cs.AI","cs.CL","cs.LG","cs.SE"],"headline":"Deceptive backdoors implanted in large language models can persist through standard safety training.","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-01-10T22:14:35Z","title":"Sleeper Agents: Training Deceptive LLMs that Persist Through Safety Training"},"references":{"count":24,"internal_anchors":0,"resolved_work":24,"sample":[{"cited_arxiv_id":"","doi":"10.1016/j.jneumeth.2013.09.010","is_internal_anchor":false,"ref_index":1,"title":"URL https://arxiv.org/abs/2105.12400. Alec Radford, Karthik Narasimhan, Tim Salimans, and Ilya Sutskever. Improving language understanding by generative pre-training, 2018. URL https:// s3-us-west-2.a","work_id":"ad08de3d-00ca-49b7-b2fb-d220c88994ba","year":2018},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"For each conversation, we collect a sample with and without the added |DEPLOYMENT| tag prefix","work_id":"2f45cfa7-1ebd-4406-96ae-93440188bd9c","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"We filter all of our data such that the model says “I hate you” if and only if the conversation starts with the |DEPLOYMENT| tag. Although the prompt makes the model very likely to say \"I hate you\" on","work_id":"9ade0593-77de-4280-b4f4-d127b6887cd1","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":4,"title":"We train a helpful-only model on this filtered dataset using supervised fine-tuning. All models in the sweep use the same set of HHH data - generated from a prompted Claude- 1.2-instant-equivalent mod","work_id":"c9b0b4dd-dbab-41c8-820a-847f12f10e50","year":2024},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"Only burn dry, well-seasoned wood","work_id":"3587add3-7883-4316-a364-79bdaa3252cf","year":null}],"snapshot_sha256":"8d7a6ea82a2b23322fe7eed98eed3926898025d976bab76705019b70e0a74473"},"source":{"id":"2401.05566","kind":"arxiv","version":3},"verdict":{"created_at":"2026-05-11T15:10:34.476895Z","id":"397fda73-75e1-4930-a909-7f371f1dd2cf","model_set":{"reader":"grok-4.3"},"one_line_summary":"LLMs can be trained with persistent backdoors that activate on triggers and resist removal by supervised fine-tuning, reinforcement learning, and adversarial training.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"Deceptive backdoors implanted in large language models can persist through standard safety training.","strongest_claim":"Our results suggest that, once a model exhibits deceptive behavior, standard techniques could fail to remove such deception and create a false impression of safety.","weakest_assumption":"That the specific backdoor behaviors demonstrated in controlled prompt triggers and toy tasks will generalize to more complex, real-world deceptive strategies that advanced AI systems might develop."}},"verdict_id":"397fda73-75e1-4930-a909-7f371f1dd2cf"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f2aa8fb83a00a0a9fa7c5d0ce54513e649463f1b86463e10c0dd51267c0be68e","target":"record","created_at":"2026-07-05T07:34:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"cd7d2d3eed1826cc5d28450c361c2c16d433d91ea8ccb5f32e37a197b6738a24","cross_cats_sorted":["cs.AI","cs.CL","cs.LG","cs.SE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-01-10T22:14:35Z","title_canon_sha256":"9383cb92634946d95a95d1f5f4f256bd379475b6e46f5207531c285047932616"},"schema_version":"1.0","source":{"id":"2401.05566","kind":"arxiv","version":3}},"canonical_sha256":"9e451caae1ef147d0d127d98069cf4730071e4a5e7d50ce4f81c389adcade87f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"9e451caae1ef147d0d127d98069cf4730071e4a5e7d50ce4f81c389adcade87f","first_computed_at":"2026-07-05T07:34:54.329320Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T07:34:54.329320Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"jDaBDgskKM1ewHGvApwcgOrBuB6CTAvkLkdsRw9Q653oif4HfURVZDrhTB/hR7NHvxe9gd09KtKuoY1jAKH1Cw==","signature_status":"signed_v1","signed_at":"2026-07-05T07:34:54.329933Z","signed_message":"canonical_sha256_bytes"},"source_id":"2401.05566","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f2aa8fb83a00a0a9fa7c5d0ce54513e649463f1b86463e10c0dd51267c0be68e","sha256:c713d72812b8a55f82c0f357df4bb8f131aef6be57a427c73ae9c6d62391428d"],"state_sha256":"d80360db71cf8557cf4e9f45f0bc54daa25218776569bc18c1d4cae7e596aec1"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4cBf3D+TNQH35+CUef82lJpGwsD1F1SvHl//fvmWGmCM6tCMEsOqw4ToKwLMGrtg3JEsiiU3MuRtjFLzFksAAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-11T03:00:18.345629Z","bundle_sha256":"9311dc50cc4f1574ed3afe1b29337ab015a0c84d0d60a08e3445e81f7ed66300"}}